# CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation

Please read this important update from Check Point.

## Security Alert:

**High**

## Product
Multi-Domain Security Management, Security Management

## Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10

## Last Modified
2026-07-22

## Symptoms

- **Impact:** An unauthenticated attacker can run any command on the Management including run-script and exec-command on Security Gateway (Check Point Firewall).

- **Affected Products and versions:**
  - Products: Security Management, Multi-Domain Security Management Server (MDS)  
  - Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10

- **Conditions:** Successful exploit requires management access without Firewall protection OR **no restrictions** on **Trusted Clients** (GUI clients).

- This issue received the ID [CVE-2026-62144](https://www.cve.org/CVERecord?id=CVE-2026-62144).

### Mitigation

1. Follow the [Check Point Hardening Best Practices Guide](https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf).

2. Limit **Trusted Clients** (GUI clients) to trusted IP addresses/subnets.
   
   To do so,
   
   1. In SmartConsole, go to **Manage & Settings** > **Permissions & Administrators** > **Trusted Clients**.
   2. Double-click the client you want to edit.
   3. In the **Trusted Client** configuration window that opens, change the settings as needed.
      - Make sure do not use "Any" as a Type.
   4. Click **OK**.

3. Protect Management access with Firewall, restrict access to trusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

## Article Properties

- Access Level: General
- Severity: High
- Status: Approved
- Date Created: 2026-07-14
- Last Modified: 2026-07-22
